What does a state sales tax auditor's first Information Document Request include?

A state sales tax auditor's first Information Document Request asks for six core record sets: sales journals by period, transaction-level calculation logs, filed returns and remittance confirmations, exemption and resale certificates, shipping and delivery records, and marketplace settlement reports. What the auditor leads with, and how the production is scoped, both signal where the assessment risk is concentrated before fieldwork begins.

Last updated: Aug 3, 2026 Sales Tax at Scale Team

Key takeaways

  • Six core categories open the IDR across CA CDTFA, NY DTF, and TX Comptroller audit manuals: sales journals by period, transaction-level calculation logs, filed returns and remittance confirmations, exemption and resale certificates, shipping and delivery records, and marketplace settlement reports.
  • The lead item signals the audit's direction. A request that leads with exemption certificates signals an exempt-sale reclassification focus; one that leads with calculation logs signals a sourcing or rate-accuracy focus; one that leads with marketplace settlement reports signals a multi-channel offset focus.
  • Scope is negotiable at the IDR stage. Sample period, native data exports versus reformatted extracts, and the choice between producing extracts and granting system access are all negotiated before fieldwork begins. The brand that produces in the broadest form invites the broadest audit.
  • The reconciliation chain runs from sales journals to calculation logs to filed returns to remittance confirmations; a clean, indexed package that ties the four links compresses sampling and signals controls.
  • Response windows typically run 10 to 30 days per IDR cycle. Extensions are routinely granted on first ask but require a written request submitted before the deadline; silence on a deadline authorizes the auditor to complete fieldwork with whatever records are already in hand.
  • The opening IDR is the moment the brand's documentation discipline gets graded. A reconciled, indexed production tends to resolve at the field-auditor level; an unindexed data dump escalates into expanded sampling and supervisor-level review.

What does the auditor's first Information Document Request include?

The CA CDTFA Audit Manual, [1] NY DTF Publication 130-D, [2] and TX Comptroller Audit Procedures Manual [3] describe substantially the same opening request. Vocabulary varies across states. California issues an Audit Engagement Letter with an attached document list; New York leads with a Records Review Request; Texas issues an Audit Questionnaire followed by a formal records request. The underlying inventory is consistent across the three highest-volume audit states for multi-channel ecommerce.

Category
What the auditor wants to see
What the brand produces
Sales journals, by period
Gross sales population by jurisdiction, the base from which everything else is reconciled
Period exports from Shopify Plus, BigCommerce, NetSuite, or QuickBooks Online, with state, taxable amount, exempt amount, and tax collected
Transaction-level calculation logs
Rate applied to each line, jurisdiction sourcing decision, taxability determination
A dated CSV from the tax calculation engine with date, jurisdiction code, taxable amount, rate applied, and tax computed per transaction
Filed returns and remittance confirmations
What was reported and what was paid for each period and registration
Copies of all filed returns with payment confirmation, or CSP filing confirmation for SST states
Exemption and resale certificates
Documentation supporting every transaction claimed exempt
The certificate file organized by buyer, by state, with effective and expiration dates
Shipping and delivery records
Destination sourcing confirmation; where the goods went, which determines the taxing jurisdiction
Carrier shipping records or 3PL exports tying each order to a ship-to address
Marketplace settlement reports
What each marketplace remitted by state and period, and how that maps to the credit taken on the seller's return
Settlement exports from Amazon, Walmart Marketplace, Faire, and TikTok Shop for the full audit period

The list looks comprehensive because it is. The opening IDR is the auditor's attempt to establish the universe of records that will support or contest every later finding. What the request does not yet include, including sampling parameters, projection methodology, and contested taxability positions, comes in later IDR cycles after the field auditor has reconciled what arrived in this one against the filed returns.

For a Shopify Plus brand operating across 25 to 40 state registrations and two to four marketplace channels, the day-one production is a documentation project before it is an accounting project. The records exist. The question is whether they can be assembled in the right form, on the right schedule, without pulling the staff accountant off the monthly close for three weeks.

How to read the opening IDR for signals about audit direction

The opening IDR is more revealing than it looks. The controllers TaxCloud has watched run productive opening conferences read the request order before they touch the document inventory. What category sits at the top of the list, what is requested in unusual detail, what is specified as a native export rather than a reformatted report. The IDR is not a generic checklist. It is the auditor's bet on where the assessment is going to come from.

Three patterns recur often enough to be diagnostic.

A request that leads with exemption and resale certificates

This signals an exempt-sale reclassification focus. The auditor expects to find missing certificates, expired certificates, or certificates on the wrong form for the state, and intends to reclassify those exempt transactions as taxable. Brands with significant B2B or wholesale revenue, drop-ship arrangements, or buyer bases of 15 or more states see this pattern most often. The defensive position is a complete, current, organized certificate library with expiration tracking and buyer registration verification, ready to produce in the first cycle.

A request that leads with transaction-level calculation logs

This signals a sourcing or rate-accuracy focus. The auditor intends to test whether the calculation engine applied the correct rate at the correct jurisdiction to each transaction. Brands operating across Colorado home-rule cities, Louisiana parishes, or the stacked Cook County, RTA, Chicago, and state rate components see this pattern. The auditor usually asks for the calculation log in native format, not a summary, because they intend to recompute a sample of transactions independently and compare. TaxCloud's reporting API exports transaction-level calculation logs for any period as a dated CSV with date, jurisdiction code, taxable amount, rate applied, and tax computed: the same fields the auditor will reconcile against, in the same field order, sourced from the calculation record that produced the filed returns.

A request that leads with marketplace settlement reports

This signals a multi-channel offset focus. The auditor expects to find a gap between what the marketplace remitted, what the brand credited on its returns, and what the brand collected directly. Brands with Amazon volume above 30 percent of total revenue, Walmart Marketplace presence, TikTok Shop, or Faire wholesale see this pattern. The auditor wants settlement exports by state and period that reconcile to the credits taken, not aggregate annual totals.

Read past the lead item. Notice what the auditor specifies as a native export rather than a reformatted report; that is the record the auditor intends to test independently. Notice what date range they ask for that exceeds the audit period by a quarter or two; that is the trailing-nexus check. Notice what they ask in unusual granularity, including buyer name and address on every exempt transaction, ship-to address on every order, or rate detail on every line. That is where the sampling will land. The IDR tells the brand where the assessment risk is concentrated before fieldwork begins, which is the only time the brand can still shape the production to address it.

What's negotiable at the IDR stage: sample period, data format, system access

Scope is negotiable and brands leave that on the table. The opening IDR is a request, not a final scope. Three dimensions are negotiable before fieldwork begins, and the brand that hands over everything in the broadest form invites a broader audit than one that scopes the production tightly.

Sample period

The IDR typically asks for records covering the full proposed audit period: three years in most states, four in Texas (Tex. Tax Code §111.0041). [4] Some categories, including exemption certificates, marketplace settlement, and shipping records, do not need to be produced for the entire period in the first cycle. Negotiate a phased production: the most recent year in the opening IDR, earlier periods in subsequent cycles as the auditor's reconciliation surfaces specific questions. This compresses the first cycle without conceding records; the auditor still receives everything they are entitled to, just not all at once.

Native exports versus reformatted extracts

Auditors prefer native system exports because they want to verify the data has not been manipulated. Brands often prefer reformatted extracts because they can apply judgment to category mapping or exemption classification. The negotiation matters most for the calculation log. A native export from the tax calculation engine carries the rate determination and jurisdiction sourcing decision as the engine made them; a reformatted extract carries whatever the brand mapped the columns to. The auditor will treat the reformatted version as the brand's interpretation, not the source record. Where the underlying data is clean, produce native. Where the underlying data needs context, such as sales journals across multiple commerce platforms with inconsistent SKU taxonomies, produce both: the native export for reconciliation, the reformatted version with an explanatory cover note.

Extracts versus system access

A growing share of state audit divisions request limited read access to the brand's accounting and tax systems rather than extracts. CA CDTFA, NY DTF, and TX Comptroller field auditors increasingly accept either approach. System access lets the auditor see more and the brand produce less; the trade-off is real. Access lets the auditor pull records the brand did not anticipate producing, including aged records outside the proposed audit period. Extracts give the brand control over what the auditor sees and a documented audit trail of what was produced. At the $20M to $80M band, the right answer is almost always extracts. Brands at this scale generally do not have the system-level access controls (auditor-only read roles, query logs, period restrictions) that make limited access defensible. Document the format choice in writing at the opening conference and reference it in subsequent IDR cycles.

Each of these is a conversation at the opening conference, not a fight. The auditor knows the brand has a right to scope the production. The auditor also knows that a brand proposing a reasonable, structured production schedule has thought about what records it has, and that thinking signals controls before a single record is delivered. The brand that hands over everything in the broadest form, in whatever format the system exports, signals the opposite.

The reconciliation chain: how the production package is built

The reconciliation chain is what the auditor is actually examining. Every other category in the IDR feeds into one of four links. The opening IDR's structure tells the brand what to assemble. The production format tells the auditor whether the brand assembled it.

The chain runs from left to right:

  1. Sales journals establish the gross sales population by state and period.
  2. Transaction-level calculation logs show what tax was computed at the line level, at which jurisdiction, at which rate.
  3. Filed returns show what was reported to the state for each period and registration.
  4. Remittance confirmations show what was actually paid, through direct bank transfer or through a Certified Service Provider for SST states.

For each gap between two consecutive links, the auditor will look for an explanation. A transaction in the sales journal that is not in the calculation log is uncollected tax until explained. A calculation log entry that is not on the filed return is reported-but-not-remitted tax. A return that does not match the remittance record is a payment failure or a CSP reconciliation gap. Each gap is a finding unless the documentation closes it.

The production package that ties the chain together has three components.

An index document

A spreadsheet, by state and period, that lists every file in the production, identifies which link in the chain it covers, and notes any reconciling items. The auditor opens the index first. If it ties the production together cleanly, the rest of the production is read for what it confirms, not for what it might be hiding.

Reconciling notes for each gap

Where the sales journal and calculation log totals differ, a one-paragraph explanation: the gap is reported manual orders, a refund timing difference, or a marketplace credit applied to the period. Identifying the gap before the auditor does signals controls; explaining the gap with the supporting record reduces the chance it becomes a sampling target.

Source documentation for each link

Sales journals exported from Shopify Plus, NetSuite, or QuickBooks Online with the standard fields (date, customer, taxable amount, exempt amount, tax collected); calculation logs from the tax engine; filed returns and payment confirmations from the compliance provider; for SST states, the consolidated CSP filing statement with the brand's allocation. TaxCloud generates the calculation log and SST filing artifacts for any period through the reporting API as dated exports, with the audit-period structure already aligned to the state's measurement window. The chain ties without recutting calendar-year data to fiscal-year audit periods.

The chain is what the auditor sees. The reconciling notes are what tell the auditor whether they need to test it themselves.

Production format, delivery, and response timing

How the production is delivered shapes the auditor's read. A clean, indexed, reconciled package tells the auditor the brand has controls. A disorganized data dump invites deeper sampling because the auditor cannot trust the population. The same records, produced the two different ways, can move a final assessment by an order of magnitude.

Four format conventions hold across CA CDTFA, NY DTF, and TX Comptroller productions:

File naming

Every file encodes state, period, and document type: CA_2024-Q3_SalesJournal.xlsx, CA_2024-Q3_CalculationLog.csv, CA_2024-Q3_FiledReturn.pdf. The convention is sortable, predictable, and lets the auditor locate any specific document in seconds. The opposite, files named for who exported them with timestamps and version numbers attached, produces a production the auditor has to triage before they can examine.

Folder structure

Three levels: state, then period, then document type. One top-level folder per registered state. Within each, one subfolder per filing period. Within each period, one folder per document category. The structure mirrors the chain: anyone in the auditor's office can open the California Q3 2024 folder and see sales journal, calculation log, filed return, certificates active during the period, settlement reports, and bank reconciliation, in that order.

Delivery method

States vary. CA CDTFA accepts secure file transfer through its auditor portal or an SFTP drop. NY DTF prefers physical media or its secure messaging system. TX Comptroller accepts both. Whatever the channel, the production should be delivered in one batch per IDR cycle, with the index document at the root level, not spread across multiple emails or transfers over the course of the response window.

Written confirmation of delivery

Every production is logged: what was delivered, on what date, in what format, with which index. The log is part of the audit file the brand keeps independently of what the state retains. If the auditor later claims a document was not produced, the log is the evidence chain.

Response windows run 10 to 30 days per IDR cycle. CA CDTFA typically allows 15 to 30 days; NY DTF and TX Comptroller commonly allow 10 to 15. Extensions are routinely granted on first ask, often 10 to 15 additional days, but the request must be submitted in writing before the deadline. Silence on a deadline authorizes the auditor to proceed with whatever records are already in hand, which is the path to the least favorable projection available. Treat every IDR deadline as a hard date and the extension request as a separate work item that runs alongside the production work.

What the production-ready operating model looks like

By the time the first IDR lands, the documentation discipline the brand built before today's date is what gets graded. The brand has the notice, the opening conference is closed, the first IDR has arrived, and the question is whether the documentation discipline it built before today's date is going to hold under examination.

Three patterns hold across audits that close at the field-auditor level rather than escalating.

The records were assembled before they were requested

A pre-notice gap index, a spreadsheet listing every state, every period, every document category, with a complete-or-missing cell for each, was maintained quarterly. Missing cells were closed before the notice arrived. When the IDR landed, the production was a retrieval operation, not a research operation.

The reconciliation was tested independently before delivery

The brand reconciled sales journals to calculation logs to filed returns to remittance for each state and period in the audit window before producing anything. Gaps were identified, explained, and documented with the supporting record attached. Nothing the auditor finds in the production should surprise the brand.

The custodian was named

Each state folder had a custodian and a backup. When the auditor asked for the Texas Q2 2023 calculation log on a Tuesday, the file was retrieved by Wednesday by someone who built the folder structure or its backup. Retrieval did not become an all-hands search during an active audit.

The reader here is past wondering whether the IDR will arrive. The question is what the production layer looks like when it does. TaxCloud is built for that supply layer: transaction-level calculation logs through the reporting API for any period on demand, consolidated SST filing statements across the 23 full member states exportable by period with the CSP confirmation attached, and an exemption certificate library with expiration tracking and buyer registration verification organized by state. The controller and the staff accountant own the audit response, the legal positions, and the negotiation with the auditor. The production-ready operating model means the documentation arrives ready to support them.

Sources

  • California Department of Tax and Fee Administration

    Audit Manual and audit guidance covering sales and use tax audit procedures

    Source link
  • New York State Department of Taxation and Finance

    Publication 130-D, The New York State Tax Audit

    Source link
  • Texas Comptroller of Public Accounts

    Audit procedures for sales and use tax

    Source link
  • Texas Constitution and Statutes

    Texas Tax Code section 111.0041 covering records retention requirements

    Source link
  • California Legislative Information

    California Revenue and Taxation Code section 6487 covering limitations and related records rules

    Source link
  • New York State Department of Taxation and Finance

    New York sales tax publications and guidance, including recordkeeping references tied to Tax Law section 1135

    Source link
  • Streamlined Sales Tax Governing Board

    Member state information showing 23 full member states and Tennessee as the associate member as of July 28, 2026

    Source link

FAQ

Common questions

How does a state sales tax auditor's first Information Document Request compare to a federal income tax auditor's initial document request?

A federal income tax auditor's initial request works from aggregate financials: general ledger, income statement, balance sheet, supporting schedules. A state sales tax auditor's opening IDR reaches transaction-level detail in the first cycle: the calculation log showing the rate applied to each line item, the certificate for each exempt sale, settlement reports tying every marketplace-collected dollar to the credit taken on the return. The granularity gap is significant. A multi-state ecommerce brand may produce tens of thousands of transaction records for a single state's two-year audit period from the opening IDR alone.

Can we negotiate the audit period in the opening IDR if the proposed scope exceeds the statutory limit?

Yes. The proposed period in the opening IDR is the auditor's starting position, not the final scope. California uses a three-year limitation period (Cal. Rev. & Tax. Code §6487), [5] Texas uses four years (Tex. Tax Code §111.0041), [4] and New York uses three years (NY Tax Law §1135). [6] The state can extend the period for fraud, substantial underreporting, or non-filing, but the burden is on the state to support the extension. Request that the period be confirmed in writing at the opening conference and reflected accurately in the first IDR. If the period extends because of unfiled returns or pre-registration exposure, the right remediation path is often a voluntary disclosure agreement rather than full cooperation with an extended audit.

What format does the auditor want for the calculation log: native export or reformatted spreadsheet?

Native, almost always. The calculation log is the record the auditor will use to recompute a sample of transactions independently. A reformatted version with custom columns or mapped fields will be treated as the brand's interpretation, not the source record. Produce the native CSV from the calculation engine with date, jurisdiction code, taxable amount, rate applied, and tax computed. If the brand needs to add context, for example a column mapping internal SKU codes to taxability categories, provide it as a supplemental file with an explanatory cover note, not as a replacement for the native export.

What happens if records for part of the audit period are unavailable?

Document the recovery attempt and the outcome before producing the rest. Marketplace platforms retain settlement data for at least seven years through seller portals; if historical data is no longer accessible through the standard interface, file a formal records request with the marketplace and preserve the correspondence. For accounting system data that predates a platform migration, retrieve from backups or from the predecessor provider where possible. For genuinely unrecoverable periods, documenting the recovery attempt supports a more defensible audit posture and a more limited estimation method than silence on the gap.

Should we grant the auditor read access to our accounting and tax systems instead of producing extracts?

In most cases, no. Extracts give the brand control over what the auditor sees and a documented audit trail of what was produced. System access lets the auditor pull records the brand did not anticipate producing, including aged records outside the proposed audit period. Limited read access is defensible when the brand has period-restricted, auditor-only roles configured in the system with query logging in place. Without those controls, extracts are the safer production format. Document the choice in writing at the opening conference and reference it in subsequent IDR cycles.

How quickly do we need to respond to the first IDR?

Response windows typically run 10 to 30 days per cycle. CA CDTFA generally allows 15 to 30 days; NY DTF and TX Comptroller commonly allow 10 to 15. Extensions of 10 to 15 additional days are routinely granted on first request, but the request must be submitted in writing before the deadline. Missing a deadline without an approved extension authorizes the auditor to complete fieldwork with whatever records are in hand, which produces the least favorable projection. Treat the extension request as a standing work item from the day the IDR arrives.